Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md node scripts/run.mjs --sample # 先看样例
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local Chinese-language ledger checker whose disclosed behavior matches its files and does not show hidden network, persistence, or destructive activity.
Install this only if you are comfortable running a local Node-based checker over potentially sensitive institutional ledger data. It does not appear to send data out, but it also does not verify official certificate authenticity or replace local regulator review.
Referenced artifact was not completely inspected
node scripts/run.mjs --sample # 先看样例
Referenced artifact was not completely inspected
node scripts/run.mjs --sample # 先看样例
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill’s natural-language interface and outputs are explicitly written in Chinese, beginning with the file description and continuing throughout user-facing messages. There is no indication that users can choose another language or locale, which may violate a language/locale choice policy.
The file consists entirely of Chinese-language labels and content, with no indication that the skill offers language selection or that the locale restriction is intentionally limited to a Chinese-region use case. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.
The header comments state that in the free package the withheld checks are removed and only explanatory text remains, yet later constants and output text include substantive premium-check scope statements such as built-in 2026 'double reduction' timing rules in OUT_OF_SCOPE/summary.basis. This is not execution of the premium checks, but the documentation's framing that only inert explanation text remains is broader than what the file actually contains and emits.
The manifest describes the free skill as performing six free audit items, but the code also embeds five additional paid-check descriptions and returns them in checks_withheld/checks_not_run output fields. While it does not execute those checks, the behavior goes beyond a narrowly scoped checker by advertising extra premium capabilities in runtime results.
No suspicious patterns detected.